CVE-2026-53948
published 2026-06-24CVE-2026-53948: Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.23%
12.0th percentile
Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as the site, this could have been used to facilitate stored cross-site scripting against site visitors or staff. This vulnerability is fixed in 6.21.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | ghost | >= 6.19.4 < 6.21.1 | 6.21.1 |
| tryghost | ghost | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Ghost: File Upload Content-Type Spoofing
ghsa·2026-08-04
CVE-2026-53948 [MEDIUM] CWE-434 Ghost: File Upload Content-Type Spoofing
Ghost: File Upload Content-Type Spoofing
### Impact
Insufficient validation of the client-supplied `Content-Type` on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as the site, this could have been used to facilitate stored cross-site scripting against site visitors or staff.
### Vulnerable versions
This vulnerability is present in Ghost from v6.19.4 up to v6.21.0.
### Patches
v6.21.1 contains a fix for this issue.
### How to update
For self-hosters using Docker, find [Docker's official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-based Ghost instance [is documented here](https://docs.ghost
VulDB
TryGhost up to 6.21.0 API File Upload Endpoint unrestricted upload (GHSA-944x-pm95-3jpr)
vuldb·2026-06-24·CVSS 5.4
CVE-2026-53948 [MEDIUM] TryGhost up to 6.21.0 API File Upload Endpoint unrestricted upload (GHSA-944x-pm95-3jpr)
A vulnerability labeled as critical has been found in TryGhost Ghost up to 6.21.0. Affected by this vulnerability is an unknown functionality of the component API File Upload Endpoint. Executing a manipulation can lead to unrestricted upload.
This vulnerability is handled as CVE-2026-53948. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-24
Published